CVE-2026-1793Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-15: 4Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-15: 302-15
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1793 Arbitrary File Read Vulnerability in Element Pack Addons for Elementor WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1793

    Post summary

    CVE-2026-1793 is a disclosed arbitrary file read vulnerability affecting the Element Pack Addons for Elementor WordPress plugin, with details provided in the Vulmon database entry.

    0002055
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1793 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a l… https://www.cve.org/CVERecord?id=CVE-2026-1793

    Post summary

    The post discloses that CVE-2026-1793 allows arbitrary file reads in the Element Pack Addons plugin for Elementor via the SVG widget. No PoC, exploit code, active exploitation, patch, or debunking claim is provided.

    00010377
    56.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-1793 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1793 #CVE-2026-1793 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/jeGw74XVMf

    Post summary

    The tweet simply announces the new CVE‑2026‑1793 for WordPress with a severity score of 6.5, providing no additional technical or exploitation details.

    0000053
    56 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🔍 CVE-2026-1793: Path traversal flaw in bdthemes Element Pack Addons for Elementor (WordPress, ≤8.3.17). Authenticated contributors can read sensitive server files. Medium severity — audit roles & restrict access! https://radar.offseq.com/threat/cve-2026-1793-cwe-22-improper-l... https://t.co/YeDh5cgDdO

    Post summary

    The advisory reports a path traversal flaw in Element Pack Addons for WordPress that lets authenticated contributors read server files, advises auditing roles and restricting access, but does not mention exploitation tools or active attacks.

    0000023
    265 followersView on X

Explore more